Skip to main content
🎉 All exam preparation materials are available for free until 30 September 2026.

Last updated: August 2026

Practice Exam

AZ-802 — Windows Server Administrator Associate (beta)

Test your knowledge with official exam-style questions

Questions25Passing700Exam time120 min

Questions and options are shuffled each attempt

Email me this practice set

Get a link sent to your inbox so you can pick this back up anytime.

▶Microsoft Certified: Windows Server Administrator Associate (beta) — Practice Set 1: All Questions & Explanations

Full question text, answer options, and explanations for this practice set — a spoiler-free alternative is the interactive quiz above for scored, shuffled practice.

  1. 1. A branch office with unreliable WAN connectivity and limited physical security needs a local domain controller. The security team is concerned that if the server is stolen, an attacker could extract cached credentials. Which type of domain controller should you deploy to mitigate this risk while still providing local authentication?

    • A. A standard writable domain controller with BitLocker enabled
    • B. A Read-Only Domain Controller (RODC)(correct)
    • C. A global catalog server with universal group membership caching
    • D. An additional domain controller holding the PDC Emulator FSMO role

    Explanation: An RODC holds a read-only copy of the AD DS database and, by default, does not cache user credentials except for accounts explicitly permitted by the Password Replication Policy, limiting exposure if the physical hardware is compromised. A writable DC with BitLocker (A) still allows full write access and broader credential caching if compromised while running. A global catalog with universal group caching (C) addresses WAN authentication latency, not credential theft risk. Holding the PDC Emulator role (D) is unrelated to physical security concerns.

  2. 2. You suspect that FSMO role holders in your forest are experiencing issues after a domain controller was forcibly removed. Which two role types should you check for role placement and potential seizure? (Choose two.)

    • A. Forest-wide roles: Schema Master and Domain Naming Master(correct)
    • B. Domain-wide roles: RID Master, PDC Emulator, and Infrastructure Master(correct)
    • C. Site-wide roles: Global Catalog coordinator
    • D. Cluster-wide roles: Quorum Owner

    Explanation: FSMO roles are split into forest-wide roles (Schema Master, Domain Naming Master) and domain-wide roles (RID Master, PDC Emulator, Infrastructure Master); these are the five roles that must be checked and potentially seized after an unplanned DC removal. There is no such thing as a 'Global Catalog coordinator' role (C) or a 'Quorum Owner' FSMO role (D) — quorum is a failover clustering concept, not an AD DS FSMO role.

  3. 3. Your company has two divisions that operate as separate AD DS forests but need users in one forest to access shared resources in the other, without merging the forests. What should you configure?

    • A. An AD DS site link bridge
    • B. A forest trust relationship(correct)
    • C. A Read-Only Domain Controller in each forest
    • D. Universal group membership caching

    Explanation: A forest trust allows all domains in one forest to trust all domains in another forest, enabling cross-forest resource access without merging directories. A site link bridge (A) only affects replication topology within a single forest's sites. RODCs (C) are about credential security, not inter-forest trust. Universal group membership caching (D) speeds up logon in sites without a global catalog and has nothing to do with cross-forest access.

  4. 4. Your organization has offices in three cities, each with its own subnet and local domain controllers in the same domain. Users complain that logons are sometimes authenticated by a DC in another city, causing delays. What should you configure to ensure clients authenticate against the closest DC?

    • A. AD DS sites with subnet associations for each location(correct)
    • B. A separate domain for each city
    • C. Group Policy loopback processing
    • D. A forest trust between the offices

    Explanation: AD DS sites, with IP subnets correctly associated to each site, allow clients to use DC Locator to find the nearest domain controller based on the client's subnet, reducing cross-WAN authentication traffic. Creating separate domains (B) is a far more disruptive and unnecessary structural change. Loopback processing (C) affects how Group Policy applies to a computer, not DC selection. A forest trust (D) applies to separate forests, not sites within one domain.

  5. 5. You need an account that runs a scheduled Windows service across multiple servers, automatically manages its own complex password, and does not require manual password rotation or a stored credential. Which type of account should you use?

    • A. A standard user account with a non-expiring password
    • B. A Group Managed Service Account (gMSA)(correct)
    • C. The built-in Local System account
    • D. A shared administrator account

    Explanation: A Group Managed Service Account (gMSA) provides automatic password management and can be used across multiple servers, ideal for services that run on more than one host, and is the recommended approach for selecting and managing service accounts. A standard user account with a non-expiring password (A) violates security best practice by never rotating credentials. Local System (C) is a local machine identity, not usable for authenticating across multiple servers to network resources. A shared administrator account (D) violates least-privilege and auditability principles.

  6. 6. You want to deploy a standard set of desktop wallpaper, mapped drives, and printer connections to users in a specific OU, applying them without requiring a logon script, and allowing users to still change the settings afterward if desired. What should you use?

    • A. Group Policy preferences(correct)
    • B. Group Policy enforced settings
    • C. A startup script deployed via SYSVOL
    • D. AD DS fine-grained password policies

    Explanation: Group Policy preferences deliver configuration items like drive mappings, printers, and desktop settings that apply once but remain user-editable afterward, unlike enforced Group Policy settings which are continuously reapplied and typically grayed out. Enforced Group Policy settings (B) would lock the configuration and prevent user changes. A startup script (C) can achieve some of this but lacks the granular, GUI-based preference management model. Fine-grained password policies (D) apply only to password/lockout settings, not desktop configuration.

  7. 7. An administrator needs to run PowerShell commands on a remote server, and those commands must in turn access a network share on a third server using the administrator's own credentials. A direct remote session fails to access the third server. What should be configured to resolve this?

    • A. Just Enough Administration (JEA)
    • B. CredSSP or Kerberos delegation to solve the double-hop problem(correct)
    • C. Remote Desktop Gateway
    • D. Windows Admin Center gateway mode

    Explanation: The scenario describes the classic PowerShell 'double-hop' problem, where credentials used to establish the first remote session cannot be forwarded to a second hop; enabling CredSSP or configuring Kerberos constrained/resource-based delegation solves this. JEA (A) restricts what commands a user can run in a session but does not solve credential delegation across hops. RD Gateway (C) is for tunneling RDP traffic, not PowerShell remoting. Windows Admin Center gateway mode (D) is a separate management architecture and does not itself resolve double-hop authentication in raw PowerShell remoting.

  8. 8. You want to centrally apply Azure Policy-based configuration and extension management to on-premises Windows Server VMs, treating them similarly to native Azure VMs. What should you implement first?

    • A. Azure Arc-enabled servers(correct)
    • B. Azure Update Manager standalone agent
    • C. Windows Admin Center desktop mode
    • D. Storage Replica

    Explanation: Onboarding on-premises servers as Azure Arc-enabled servers projects them into Azure Resource Manager as resources, which is the prerequisite for applying Azure Policy-driven device configuration and deploying VM extensions on non-Azure machines. Azure Update Manager (B) manages updates but depends on Arc onboarding (or being a native Azure VM) to function on-premises. Windows Admin Center desktop mode (C) is a management console, not an Azure resource projection mechanism. Storage Replica (D) is unrelated — it replicates volumes for disaster recovery.

  9. 9. You need to automate a recurring maintenance task, such as stopping a service and restarting an Azure VM on a schedule, without installing custom software on each server. What Azure feature should you use?

    • A. Azure Automation runbooks(correct)
    • B. Azure Bastion
    • C. Azure File Sync
    • D. Data collector sets

    Explanation: Azure Automation runbooks let you author and schedule PowerShell or Python workflows that run centrally in Azure to automate tasks like service restarts across VMs. Azure Bastion (B) provides secure RDP/SSH access to VMs without public IPs and does not run scheduled automation. Azure File Sync (C) synchronizes file shares. Data collector sets (D) are a Performance Monitor feature for capturing performance data, not for running automation tasks.

  10. 10. A developer needs to run a nested Hyper-V lab inside a Hyper-V VM hosted on your Windows Server host. What must you configure on the parent VM to support this?

    • A. Enhanced Session Mode
    • B. Nested virtualization(correct)
    • C. GPU partitioning
    • D. Hyper-V Replica

    Explanation: Nested virtualization must be enabled on the VM's virtual processor configuration to allow that VM to itself run Hyper-V and host further nested VMs. Enhanced Session Mode (A) improves the VM connection experience (clipboard, drive redirection) but doesn't enable nested hypervisors. GPU partitioning (C) shares a physical GPU across VMs and is unrelated to nested virtualization. Hyper-V Replica (D) is a DR replication feature for VMs, not a virtualization capability toggle.

  11. 11. You need to provide temporary, tightly time-boxed RDP access to an Azure VM's management port only when an approved request is active, minimizing the VM's exposed attack surface. What should you configure?

    • A. Azure Bastion in standard SKU only
    • B. Just-in-time (JIT) VM access(correct)
    • C. An availability set
    • D. A VM scale set with autoscaling

    Explanation: Just-in-time (JIT) VM access, typically enabled through Microsoft Defender for Cloud, locks down inbound management ports and opens them only for a limited window after an approved request, minimizing exposure. Azure Bastion (A) provides a secure RDP/SSH gateway but doesn't itself implement time-boxed, request-based port opening the way JIT does. An availability set (C) is for VM fault-domain distribution, unrelated to access control. A VM scale set with autoscaling (D) manages capacity, not access security.

  12. 12. You must provide disaster recovery for a critical Hyper-V VM to a secondary site with asynchronous, VM-level replication that does not depend on shared storage or a failover cluster. Which feature should you configure?

    • A. Storage Spaces Direct
    • B. Hyper-V Replica(correct)
    • C. NIC Teaming
    • D. Storage Replica in synchronous mode

    Explanation: Hyper-V Replica provides asynchronous, VM-level replication to a secondary host or site over unreliable network links, without requiring shared storage or clustering. Storage Spaces Direct (A) pools local disks into shared storage for a cluster, a different architecture entirely. NIC Teaming (C) provides network adapter redundancy, not VM replication. Storage Replica in synchronous mode (D) replicates volumes in near real time but typically requires low-latency links and operates at the volume/storage layer rather than the VM layer.

  13. 13. Your DNS servers are receiving external queries and you're concerned about cache poisoning attacks affecting the integrity of DNS responses. Which feature should you implement to cryptographically sign zone data?

    • A. DNS conditional forwarding
    • B. DNS policies
    • C. DNS Security Extensions (DNSSEC)(correct)
    • D. Integrating DNS with AD DS

    Explanation: DNSSEC adds cryptographic signatures to DNS zone data so resolvers can validate that responses have not been tampered with, directly mitigating cache poisoning and spoofing. Conditional forwarding (A) simply routes queries for specific domains to specific DNS servers and provides no integrity protection. DNS policies (B) control response behavior based on criteria like client subnet or time of day, not cryptographic validation. AD-integrated DNS (D) improves replication and security of zone transfers within AD DS but does not itself provide DNSSEC-style response validation for external queries.

  14. 14. You want to ensure that if your primary on-premises DHCP server fails, clients can still obtain and renew IP address leases without manual intervention. What should you implement?

    • A. DHCP failover(correct)
    • B. DNS forwarding
    • C. A DHCP relay agent only
    • D. IP address reservations

    Explanation: DHCP failover lets two DHCP servers share lease information and continue serving clients if one server becomes unavailable, providing high availability for DHCP. DNS forwarding (B) is unrelated to DHCP lease availability. A DHCP relay agent alone (C) forwards broadcast DHCP requests across subnets but does not provide redundancy if the DHCP server itself fails. IP address reservations (D) ensure a specific device always receives the same address but don't address server availability.

  15. 15. Users at a branch office report that internal hostnames resolve correctly, but the same clients occasionally get connected to the wrong regional application endpoint compared to users at headquarters, even though both offices query the same DNS server. You want responses to differ based on the client's originating subnet. What should you configure?

    • A. A DNS policy with client subnet criteria(correct)
    • B. A DHCP scope for each office
    • C. A conditional forwarder pointing to the application vendor's DNS
    • D. An RODC at each branch

    Explanation: DNS policies allow a single DNS server to return different responses to the same query based on criteria such as the client's subnet, enabling location-aware responses like regional endpoint steering. A DHCP scope (B) governs IP address assignment, not DNS response logic. A conditional forwarder (C) routes entire domain queries to another DNS server uniformly, not selectively by client location. An RODC (D) is a domain controller role and has no bearing on subnet-aware DNS responses.

  16. 16. You are migrating an on-premises DFS Namespace deployment to a cloud-based file synchronization model while keeping a local cache of frequently accessed files on-premises. What should you implement?

    • A. Azure File Sync with cloud tiering(correct)
    • B. Storage Replica
    • C. Data Deduplication
    • D. Storage Spaces Direct

    Explanation: Azure File Sync, with cloud tiering enabled, centralizes file data in Azure file shares while caching frequently used files locally on the Windows Server endpoint, which is the recommended migration path from DFS to Azure Files. Storage Replica (B) replicates block storage between servers or clusters, not a cloud file-sync/caching model. Data Deduplication (C) reduces storage consumption by eliminating duplicate blocks, unrelated to cloud synchronization. Storage Spaces Direct (D) pools local disks for a hyper-converged cluster and has no direct role in DFS-to-cloud migration.

  17. 17. You need to enforce a quota on a file share and automatically notify administrators when usage nears the limit, as well as block specific file types like executables from being stored. What feature should you configure?

    • A. File Server Resource Manager (FSRM)(correct)
    • B. SMB over QUIC
    • C. Storage QoS
    • D. ReFS integrity streams

    Explanation: FSRM provides quota management, file screening (blocking file types), and reporting/notification capabilities for Windows Server file shares. SMB over QUIC (B) is a transport enhancement for secure SMB access over untrusted networks, unrelated to quotas. Storage QoS (C) manages storage performance/IOPS allocation, not quotas or file screening. ReFS integrity streams (D) protect against data corruption using checksums, not quota enforcement.

  18. 18. You are designing storage for a Storage Spaces Direct hyper-converged cluster that requires high performance and resiliency without a SAN. Which two capabilities are most relevant to plan for? (Choose two.)

    • A. SMB Direct using RDMA-capable NICs for low-latency east-west storage traffic(correct)
    • B. Storage Spaces Direct pooling local disks across cluster nodes(correct)
    • C. DFS Namespace consolidation of unrelated file shares
    • D. DNSSEC zone signing for the cluster's DNS records

    Explanation: Storage Spaces Direct pools local, directly attached disks across cluster nodes into a single software-defined storage layer, and SMB Direct with RDMA-capable NICs is commonly used to deliver the low-latency, high-throughput network fabric that S2D relies on between nodes. DFS Namespace consolidation (C) is a separate file-sharing feature unrelated to the underlying storage fabric. DNSSEC (D) is a DNS security feature with no bearing on storage cluster performance or resiliency design.

  19. 19. A volume containing sensitive data was encrypted with BitLocker, and the recovery key is required after a TPM state change flagged the drive as locked. Where would you look first to retrieve the recovery key if it was backed up to AD DS?

    • A. The computer object's BitLocker Recovery tab in AD DS(correct)
    • B. The DNS zone properties
    • C. The FSRM quota template
    • D. The Storage Replica partnership log

    Explanation: When BitLocker recovery information is backed up to AD DS, it is stored as a property of the associated computer object, and administrators can view it under a BitLocker Recovery tab in tools like Active Directory Users and Computers. DNS zone properties (B) have nothing to do with encryption keys. FSRM quota templates (C) manage storage quotas, not recovery keys. Storage Replica partnership logs (D) track replication status, not BitLocker recovery data.

  20. 20. You want to prevent domain administrator credentials from being cached in a way that lets them be extracted using pass-the-hash or pass-the-ticket techniques when an admin signs in to a lower-trust server. Which feature should you implement?

    • A. Windows Defender SmartScreen
    • B. Credential Guard(correct)
    • C. Windows Firewall connection security rules
    • D. Exploit protection mitigation policies

    Explanation: Credential Guard uses virtualization-based security to isolate and protect secrets (such as NTLM hashes and Kerberos tickets) so that even a compromised OS kernel cannot extract them, directly mitigating pass-the-hash and pass-the-ticket attacks. SmartScreen (A) helps block malicious downloads and sites, not credential theft techniques. Windows Firewall connection security rules (C) govern IPsec-based traffic authentication, not in-memory credential protection. Exploit protection (D) mitigates memory-corruption exploitation techniques (like ASLR/DEP-style protections), which is a different threat category.

  21. 21. You need to ensure local administrator account passwords on member servers are unique per machine, automatically rotated, and retrievable only by authorized administrators from AD DS. Which solution addresses this?

    • A. Windows Local Administrator Password Solution (LAPS)(correct)
    • B. Protected Users security group
    • C. Fine-grained password policies
    • D. OSConfig security baselines

    Explanation: Windows LAPS automatically manages and rotates local administrator passwords per machine and stores them securely in AD DS (or Microsoft Entra ID), with access restricted through delegated permissions. The Protected Users group (B) restricts how a domain account's credentials can be used/cached but does not manage local admin passwords. Fine-grained password policies (C) apply different domain password/lockout policies to different sets of domain users, not local account passwords. OSConfig baselines (D) apply consistent security configuration baselines but don't perform local password rotation.

  22. 22. Security auditors want assurance that even if a domain user's credentials are phished, the attacker cannot use NTLM to authenticate as that user and that the account's Kerberos tickets have a shortened lifetime. Which built-in group should the account be added to?

    • A. Protected Users(correct)
    • B. Domain Admins
    • C. Backup Operators
    • D. Remote Management Users

    Explanation: The Protected Users group applies restrictions such as disabling NTLM authentication, disabling DES/RC4 for Kerberos pre-auth, and enforcing shorter Kerberos ticket lifetimes for its members, hardening high-value accounts against credential theft and replay. Domain Admins (B) grants elevated privileges but applies no such credential-hardening restrictions by itself. Backup Operators (C) grants backup/restore rights and is unrelated to authentication hardening. Remote Management Users (D) grants WinRM access, not credential protections.

  23. 23. You want to capture detailed performance counter data over a scheduled window (for example, CPU, memory, and disk counters every 15 seconds for 24 hours) for later trend analysis, without manually watching a live console. What should you configure?

    • A. A data collector set in Performance Monitor(correct)
    • B. Event log subscriptions
    • C. VM Insights
    • D. System Insights capacity forecasting only

    Explanation: Data collector sets in Performance Monitor let you define specific counters, sampling intervals, and schedules to capture performance data over time for later analysis, exactly matching the scenario. Event log subscriptions (B) forward Windows event log entries, not performance counter samples. VM Insights (C) is an Azure Monitor feature focused on Azure VM performance and dependency mapping, not local scheduled counter logging. System Insights (D) provides predictive capacity analytics on the server itself but is not the mechanism for defining custom scheduled counter captures.

  24. 24. An administrator accidentally deleted an OU containing several user accounts. AD Recycle Bin is enabled. What is the appropriate recovery approach?

    • A. Restore the objects directly from the AD Recycle Bin(correct)
    • B. Boot into Directory Services Restore Mode and perform an authoritative restore from backup
    • C. Manually recreate each user account with the same name
    • D. Force replication from a backup domain controller

    Explanation: Since AD Recycle Bin is enabled, deleted objects (including their attributes and group memberships) can typically be restored directly and non-disruptively without needing to reboot a domain controller into Directory Services Restore Mode. DSRM authoritative restore (B) is a valid recovery technique but is more disruptive and generally reserved for scenarios where AD Recycle Bin isn't enabled or backups must be used. Manually recreating accounts (C) loses the original SIDs and group memberships. Forcing replication (D) would not restore already-replicated deletions and could propagate the deletion further.

  25. 25. Users report intermittent failures accessing resources that require Kerberos authentication on a specific member server, even though the domain itself appears healthy. Other servers are unaffected. What should you investigate first?

    • A. The secure channel and computer account trust for that specific member server(correct)
    • B. The forest-wide Schema Master role holder
    • C. The DHCP scope options for the subnet
    • D. The FSRM quota configuration on that server

    Explanation: Kerberos authentication failures isolated to a single member server, while the rest of the domain functions normally, are a classic symptom of a broken secure channel or computer account trust relationship (for example, after the machine account password fell out of sync), and should be investigated first with tools like Test-ComputerSecureChannel. The Schema Master (B) affects schema changes forest-wide and wouldn't cause a single-server authentication issue. DHCP scope options (C) affect IP configuration, not Kerberos trust. FSRM quotas (D) govern storage usage and are unrelated to authentication failures.